summaryrefslogtreecommitdiffstats
path: root/install/share/krb5.conf.template
diff options
context:
space:
mode:
authorJakub Hrozek <jhrozek@redhat.com>2011-02-10 21:47:45 +0100
committerRob Crittenden <rcritten@redhat.com>2011-02-14 14:45:22 -0500
commit22c3a681da7ec5c84e8822eb325c647a8e89942a (patch)
tree83813eacd9ee4050e4430101a048ad7cd416f1d5 /install/share/krb5.conf.template
parentc9431749a0078df8bdf13490daac5f3467cc1c02 (diff)
downloadfreeipa-22c3a681da7ec5c84e8822eb325c647a8e89942a.tar.gz
freeipa-22c3a681da7ec5c84e8822eb325c647a8e89942a.tar.xz
freeipa-22c3a681da7ec5c84e8822eb325c647a8e89942a.zip
Fine tuning DNS options
Add pointer to self to /etc/hosts to avoid chicken/egg problems when restarting DNS. On servers set both dns_lookup_realm and dns_lookup_kdc to false so we don't attempt to do any resolving. Leave it to true on clients. Set rdns to false on both server and client. https://fedorahosted.org/freeipa/ticket/931
Diffstat (limited to 'install/share/krb5.conf.template')
-rw-r--r--install/share/krb5.conf.template5
1 files changed, 3 insertions, 2 deletions
diff --git a/install/share/krb5.conf.template b/install/share/krb5.conf.template
index 9cf4ee84d..93d88dbb2 100644
--- a/install/share/krb5.conf.template
+++ b/install/share/krb5.conf.template
@@ -5,8 +5,9 @@
[libdefaults]
default_realm = $REALM
- dns_lookup_realm = true
- dns_lookup_kdc = true
+ dns_lookup_realm = false
+ dns_lookup_kdc = false
+ rdns = false
ticket_lifetime = 24h
forwardable = yes